GPO Sprawl
i took position allowed container admins (ca) add/adjust/create gpos. out of control. company has 138 ca accounts, , 636 gpo's listed. it's task under control. question pretty broad. start? have plan of attack i'd love hear others see their point of view.
deann
i took position allowed container admins (ca) add/adjust/create gpos. out of control. company has 138 ca accounts, , 636 gpo's listed. it's task under control. question pretty broad. start? have plan of attack i'd love hear others see their point of view.
deann
if in situation, following
- backup gpo in case...
- check delegation (yes, difficult task !) , remove desired users (if applicable)
ref: how view or delete active directory delegated permissions (en-us)
- check group policy creator owners group - remove users (if applicable)
- check domain admins group - remove users (if applicable)
- restrict users gpmc
- create domain level policy , link ous
- unlink unwanted gpos on ous 1 one
- instruct admins not create or link gpos without approval during gpo sanitizing phase
- before access permission revocation, make note of permissions set on containers, ids etc.. screen shots come in handy well
hth
i not represent organisation work for, opinions expressed here own.
this posting provided "as is" no warranties or guarantees , confers no rights.
- .... .- -. -.- ... --..-- ... .- -. - --- ... ....
Windows Server > Group Policy
Comments
Post a Comment